Strong Password Generator

Generate long, high-entropy passwords or diceware-style passphrases, with honest crack-time estimates and habits that actually keep accounts safe.

How it works

Password mode starts at 20 characters with all four character sets always on, the strongest practical setting for sites that accept it.

Passphrase mode picks 4-8 words at random from a built-in list of over 1,200 common words. Six words gives about 62 bits, and is far easier to remember.

Crack times assume a fast offline attack of 10 billion guesses per second against a stolen hash, finding the password halfway through on average.

Formula

Passphrase bits = words × log₂(list size) Crack time = 2^bits ÷ 2 ÷ guesses per second

Where:

words
= Number of random words
list size
= Words in the list (1,295)

Worked example

A 24-character password from 89 symbols has 24 × log₂(89) ≈ 155 bits.

A 6-word passphrase from 1,295 words has 6 × 10.34 ≈ 62 bits; at 10 billion guesses per second that's still around 7 years on average, add a word for centuries.

Security Without Forced Complexity

NIST guidance has shifted from 'complex' passwords to 'long' ones. Forced complexity often leads to predictable patterns. By focusing on 20-character minimums and using all character sets by default, this generator ensures high entropy without requiring substitutions that attackers anticipate. Passphrases are a powerful alternative, stringing random words together for extreme length that remains easy for humans to memorize.

Differentiator: Built for Extreme Resistance

This tool emphasizes 20+ character defaults and diceware-style passphrases for maximum protection. While our Random generator offers more character-level control and the Free generator offers quick presets, the Strong generator is engineered for high-stakes credentials like master vault passwords. It prioritizes the 20-128 range to ensure data remains safe against future advances in computing power and sophisticated offline cracking.

Mitigating the Threat of Offline Cracking

The real threat is offline cracking, where attackers use high-performance hardware to guess billions of hashes per second. Every extra character or word in your passphrase adds bits of entropy that multiply the time required for a match. Combining a strong, long password with two-factor authentication (2FA) creates a layered defense that protects you even if a single service is compromised.

Frequently asked questions

NIST SP 800-63B favors length over forced complexity: allow at least 64 characters, check against breached-password lists, and don't force periodic changes unless a password is compromised.

Related calculators